Initialization-Key Public Key Exchange Without Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing a secure channel between devices requires secure exchange of public keys, which conventionally involves storing certificates from a certification authority, leading to data storage inefficiencies and complexity.

Innovation Solution

Utilizing an initialization key stored during manufacturing to enable secure exchange of public keys between devices, eliminating the need for certificate storage and simplifying the key exchange process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificates from a certification authority are used to establish secure channels, then security is improved, but data storage requirements and device complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoiddata storage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the certificate authority component from the key exchange process. Instead of relying on third-party certificates, the system uses direct public key exchange between devices, eliminating the need to store and verify certificates while maintaining security through cryptographic protocols

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary initialization key that is pre-shared between devices during manufacturing. This initialization key acts as a mediator that enables secure public key exchange without requiring certificate authorities, reducing storage requirements while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If certificates from a certification authority are used to establish secure channels, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent removes the certificate verification infrastructure from the device. By using direct public key exchange mediated by an initialization key, the device no longer needs to store certificate authorities, validate certificates, or manage complex trust chains, significantly reducing device complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs the security setup action in advance during device manufacturing by pre-loading an initialization key. This preliminary action eliminates the need for complex runtime certificate management, reducing operational complexity while maintaining security

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple public keys and certificates are stored for chained certificates, then security is improved, but data storage requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoiddata storage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the entire certificate chain infrastructure from the system. By using a simplified initialization key mechanism, the system eliminates the need to store multiple certificates and public keys associated with chained certificates, dramatically reducing storage requirements

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of the conventional approach where devices store and verify others' certificates, the patent inverts the model by having devices use a pre-shared initialization key to verify each other. This reversal eliminates the need for storing multiple certificates while maintaining security

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP4005146B1Techniques for secure data exchanges
Publication Date: 2025.11.12 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP4005146B1 patent drawingFigure 1
  • EP4005146B1 patent drawingFigure 2
  • EP4005146B1 patent drawingFigure 3

AI summary

Systems and methods are disclosed for performing a secure exchange of encryption keys (e.g., public keys) between two devices. One or more initialization keys are stored at both devices. In some embodiments, at least one device (e.g., a reader device) stores the initialization key(s) (e.g., a symmetric key, an asymmetric key pair) in local memory as part of performance of a manufacturing process for the device. The second device (e.g., a thin client device) may receive the initialization key(s) from an acceptance cloud (e.g., a server computer configured to perform terminal processing). The initialization key(s) are utilized to perform a secure exchange of the devices' respective public keys. Once these public keys are exchanged, the devices may proceed to establishing a secure connection with which subsequent operations may be performed.